Graph

|Shell Type|Connection Direction|Primary Log Source|Key Indicator| |—|—|—|—| |Bind|Inbound (Attacker to Victim)|Netstat / Endpoint Logs|New Listening Port| |Reverse|Outbound (Victim to Attacker)|Firewall / Sysmon|Connection to Unknown External IP| |Web|Inbound (Over Port 80/443)|Web Server Access Logs|POST to unusual .php/.aspx files|